Koldov Posted September 13, 2021 Posted September 13, 2021 (edited) Hi, Just looking at the email message ID and added the domain eu-west-1.amazonses.com into the sending domain... As in previous post, put the Sophos domains into the 'Simulation URL' section... Edited September 13, 2021 by Koldov
Koldov Posted September 13, 2021 Posted September 13, 2021 This seems to have fixed it (for us anyway), I'm not sure if that 'sender' domain ever changes but the last few tests have come through ok. I have also removed all the other 'Allowed Domains' set in the other 'Anti-Spam' policy (and the IP addresses in the 'Connection Filter').
kennysarmy Posted September 14, 2021 Author Posted September 14, 2021 This seems to have fixed it (for us anyway), I'm not sure if that 'sender' domain ever changes but the last few tests have come through ok. [ATTACH=CONFIG]63053[/ATTACH] [ATTACH=CONFIG]63054[/ATTACH] I have also removed all the other 'Allowed Domains' set in the other 'Anti-Spam' policy (and the IP addresses in the 'Connection Filter'). Thanks for your PM and help. Seems this also fixed it for us: in the 'Advanced Delivery' settings. Sending Domain eu-west-1.amazonses.com Sending Domain staysafe.sophos.com Sending IP 54.240.51.52 Sending IP 54.240.51.53 Allowed Simulation URL gmailmsg.com
LordChappers Posted December 14, 2021 Posted December 14, 2021 Good afternoon guys, This thread has been really interesting - It seems as though every time I've done a phishing test (we do it monthly to random users) it will instantly get quarantined until I botch my way around whitelisting the address. I've now removed all of the whitelisted domains/IPs from the anti spam policies and added the Advanced Delivery settings you've advised (with some of the additional Sophos simulated URLs) but I'm still getting quarantined. Did you end up amending the 'High Confidence Phish' setting? I'm glad Defender is doing it's job, but this is maddening!
free780 Posted December 14, 2021 Posted December 14, 2021 (edited) How come people don’t use Microsoft’s built in Defender attack simulations? Adding the IPS to the Connection filter should override high confidence phishing. You can also use the tenant allow feature to allow a domain for 30 days. You can do this after you report an email is clean in threat explorer. Edited December 14, 2021 by free780
LordChappers Posted December 15, 2021 Posted December 15, 2021 Hi Free, Thanks for the reply. We don't have licences for Defender so can't use Investigations, Explorer, Campaigns, Threat Tracker, etc. We do however have Sophos Phish Threat, and have been using it monthly for a while, but every couple of months Microsoft change something that makes the emails get quarantined (I'm doing a copy of the same campaign I did in September & October, with the same dummy sender address and it's suddenly not working). I have removed all of the whitelisted addresses and IPs (including the connection filter IPs as @Koldov mentioned above) that I had set up previously and have the following in my Advanced Delivery rule, but it is still quarantining my test emails: Any help would be greatly appreciated! This situation is particularly annoying as we do the phishing tests to show that IT Support are constantly doing work, which prevents me from doing proper work, but when doing these tests (that should take minutes) I spend ages troubleshooting!
Koldov Posted December 15, 2021 Posted December 15, 2021 How come people don’t use Microsoft’s built in Defender attack simulations? Doesn't that only apply to those with the appropriate licenses? I guess not everyone has those... "Attack simulation training in Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5" https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training?view=o365-worldwide We got Sophos Phish bundled in with Sophos AV from LGfL, but unfortunately they have somehow let our licenses for it expire so I haven't sent one in a while (and I've been a little preoccupied with other things), but I don't really remember doing anything other than what was described in this thread (but then again, I don't know whether it still works either). It's been a while and a lot has happened since then, but I seem to remember looking at the quarantined messages, where they came from and what rule in the Exchange admin center was using to block them (if it comes from a different domain or says that 'an admin in your organization has set up a spam rule')... I think that MS are still making changes to the way it deals with spam/phishing so it could be that they have done something that has started blocking them again... Sorry I can't be more help!
LordChappers Posted December 15, 2021 Posted December 15, 2021 Hi @Koldov, I appreciate the reply. I've now found the culprit after looking into the headers - our email filter (Checkpoint) has been intercepting the messages, but passing them through from their IP where they then got trapped. I've added the Sophos IPs to the Checkpoint exclusion rule and it is now working. Many thanks for the help!
kennysarmy Posted November 4, 2022 Author Posted November 4, 2022 Was working well last year but my recent simulated attacks are not working because as soon as the email lands it's triggering something with Sophos to make it look like the user is clicking the link in the email. Any ideas what could be causing this? The test user hadn't even logged in to Office 365 and he was "caught"
TechMonkey Posted November 4, 2022 Posted November 4, 2022 I am guessing the link is unique to identify the user and something is following the link to check it and setting off the unique link. What spam system do you use? Would be funny if it was Sophos triggering itself!
kennysarmy Posted November 10, 2022 Author Posted November 10, 2022 I am guessing the link is unique to identify the user and something is following the link to check it and setting off the unique link. What spam system do you use? Would be funny if it was Sophos triggering itself! Think we may have narrowed it down to our Barracuda Networks' Email Gateway Defense!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now